DVSealedSessionTokenStore class

A session token sealed with AES-256-GCM under the application key before it reaches sink.

The sink holds ciphertext only, so a copy of it -- a backup, another user's process, a lost laptop's disk -- is not a working session. When the key store cannot answer, the token is not written at all: an unsealed token on disk is exactly what this exists to prevent.

Implemented types

Constructors

DVSealedSessionTokenStore({required DVSessionTokenSink sink, required Future<DVAppKeyStore> keys()})

Properties

hashCode → int
The hash code for this object.
no setterinherited
keys → Future<DVAppKeyStore> Function()
The application key store, asked only once there is something to seal or unseal: a keyring can prompt, and a launch with nothing stored should not.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sink → DVSessionTokenSink
final

Methods

clear() → Future<void>
Removes the stored token, touching the sink only when it holds one.
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
read() → Future<String?>
override
toString() → String
A string representation of this object.
inherited
write(String token) → Future<void>
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited